VDB
Sign up
HIGH8.8

GHSA-8wj3-cpmr-8whp

Cockpit Content Platform vulnerable to 2FA bypass

Quick fix

GHSA-8wj3-cpmr-8whp — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.2.2

Details

Cockpit Content Platform through version 2.2.1 is vulnerable to a two-factor authentication (2FA) bypass. The 2FA secret is disclosed in a JWT token after user logs into their account, allowing an attacker to bypass the 2FA code. A patch is available on the `develop` branch and is expected to be part of version 2.2.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.2.2
Fixcomposer require cockpit-hq/cockpit:^2.2.2

References